CVE-2024-56835: Code Injection
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0), RUGGEDCOM ROX RX1510 (All versions < V2.17.0), RUGGEDCOM ROX RX1511 (All versions < V2.17.0), RUGGEDCOM ROX RX1512 (All versions < V2.17.0), RUGGEDCOM ROX RX1524 (All versions < V2.17.0), RUGGEDCOM ROX RX1536 (All versions < V2.17.0), RUGGEDCOM ROX RX5000 (All versions < V2.17.0). The DHCP Server configuration file of the affected products is subject to code injection. An attacker could leverage this vulnerability to spawn a reverse shell and gain root access on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56835?
CVE-2024-56835 is classified as a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2024-56835?
To mitigate CVE-2024-56835, upgrade the RUGGEDCOM ROX II software to version 2.17.0 or later.
What products are affected by CVE-2024-56835?
CVE-2024-56835 affects all versions of the RUGGEDCOM ROX II family prior to version 2.17.0.
What type of attack does CVE-2024-56835 facilitate?
CVE-2024-56835 allows for code injection that can lead to a reverse shell and root access on the affected system.
Is CVE-2024-56835 being actively exploited in the wild?
As of current reports, there is no public information confirming active exploitation of CVE-2024-56835.